CVE-2026-5936
Last modified
CVE-2026-5936 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations. This behavior may be exploited to probe internal network services, access otherwise unreachable endpoints (e.g., cloud metadata services), or bypass network access controls, potentially leading to sensitive information disclosure and further compromise of the internal environment.. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests to arbitrary destinations. This behavior may be exploited to probe internal network services, access otherwise unreachable endpoints (e.g., cloud metadata services), or bypass network access controls, potentially leading to sensitive information disclosure and further compromise of the internal environment.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Foxit | Pdf Services Api | < 2026-04-07 |
References
- https://www.foxit.com/support/security-bulletins.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-5936?
How severe is CVE-2026-5936?
How do I fix CVE-2026-5936?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-59335Improper handling of case sensitivity (CWE-178) in the ident…8.7
- CVE-2026-5934The WP Rocket plugin for WordPress is vulnerable to Stored C…7.2
- CVE-2026-59341A security vulnerability exists in the Sealed Secrets contro…4.2
- CVE-2026-5935IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9…9.8
- CVE-2026-59354In versions of Spring Security's OAuth2 Authorization Server…8.8
- CVE-2026-59355In versions of Spring Authorization Server 1.5.0 through 1.5…6.1
- CVE-2026-5937Insufficient parameter verification leads to the occurrence …5.5
- CVE-2026-5938Improper control flow management allows a crafted document a…5.5
- CVE-2026-5939A crafted XFA PDF can trigger a use-after-free condition dur…5.5
- CVE-2026-5940Calling a function that triggers a UI refresh after removing…5.5
- CVE-2026-5941Parsing logic flaws cause non-signature data to be misidenti…7.1
- CVE-2026-5942Flaws in page lifecycle management allow document structure …5.5
Are you affected by CVE-2026-5936?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
